Follow

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate content-following skill with disclosed monitoring and archiving, but users should control what sources it watches and what it stores.

Install only if you intend to monitor authorized sources. Keep archives in a location you control, avoid private or regulated content unless you have permission, review any configured alert destinations, and install external tools from trusted sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly supports cross-platform monitoring, alerting, and archiving, but provides no privacy, consent, retention, or sensitive-data handling guidance. In practice, this can normalize collection and storage of personal or regulated content and lead to unauthorized monitoring, excessive retention, or disclosure through alerts and archives.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal